What do we need to know about the Chief Information Security Officer? A literature review and research agenda

被引:0
|
作者
Sahin, Zeynep [1 ]
Vance, Anthony [1 ]
机构
[1] Virginia Tech, Pamplin Coll Business, Dept Business Informat Technol, Pamplin Hall 880W Campus Dr Suite, Blacksburg, VA 24061 USA
关键词
Chief information security officer (CISO); Board of directors; Executives; Cybersecurity governance; Literature review; Research agenda; UPPER ECHELONS; SYSTEMS; MANAGEMENT; WORK; ORGANIZATION; ANTECEDENTS; LEGITIMACY; CHALLENGES; LEADERSHIP; IMPACT;
D O I
10.1016/j.cose.2024.104063
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Since its establishment in the 1990s, the role of chief information security officer (CISO) has become critical to organizations in managing cybersecurity risks. However, despite widespread recognition of the importance of this role in industry, research about CISOs and the problems they face in protecting organizations is nascent. We review the academic and practitioner literature on CISOs to identify existing themes and highlight a range of challenges related to CISOs in which further research is needed, such as establishing legitimacy within C-suite executive teams, appropriate accountability for cybersecurity incidents, CISO turnover, and promoting security in the face of human factors, business realities, and budget constraints. We also propose a research agenda to address these challenges using potential theoretical lenses. In these ways, this study lays the groundwork for future research on CISOs and their essential role in ensuring the cybersecurity of organizations.
引用
收藏
页数:19
相关论文
共 50 条
  • [1] What Do We Know about the Chief Digital Officer? A Literature Review
    Moker, Anna
    AMCIS 2020 PROCEEDINGS, 2020,
  • [2] The art of writing literature review: What do we know and what do we need to know?
    Paul, Justin
    Criado, Alex Rialp
    INTERNATIONAL BUSINESS REVIEW, 2020, 29 (04)
  • [3] What do we need to know about global food security?
    Cassman, Kenneth G.
    GLOBAL FOOD SECURITY-AGRICULTURE POLICY ECONOMICS AND ENVIRONMENT, 2012, 1 (02): : 81 - 82
  • [4] What about the Chief Digital Officer? A Literature Review
    Rakovic, Lazar
    Maric, Slobodan
    Milutinovic, Lena Dordevic
    Sakal, Marton
    Antic, Slobodan
    SUSTAINABILITY, 2022, 14 (08)
  • [5] What we do not know about advergames: a literature review
    Sanz, Laura Cante
    de la Hera, Teresa
    FRONTIERS IN COMMUNICATION, 2023, 8
  • [6] What we know, what we do not know, and what we should and could have known about workplace bullying: An overview of the literature and agenda for future research
    Nielsen, Morten Birkeland
    Einarsen, Stale Valvatne
    AGGRESSION AND VIOLENT BEHAVIOR, 2018, 42 : 71 - 83
  • [7] What We Know and What We Need to Know about Undergraduate Research
    Haeger, Heather
    Banks, John E.
    Smith, Camille
    Armstrong-Land, Monique
    SPUR-SCHOLARSHIP AND PRACTICE OF UNDERGRADUATE RESEARCH, 2020, 3 (04): : 62 - 69
  • [8] RESEARCH - WHAT DO WE NEED TO KNOW
    BROWN, RH
    GEORGIA AGRICULTURAL RESEARCH, 1982, 22 (04): : 4 - 5
  • [9] Sugammadex: what do we know and what do we still need to know? A review of the recent (2013 to 2014) literature
    Ledowski, T.
    ANAESTHESIA AND INTENSIVE CARE, 2015, 43 (01) : 14 - 22
  • [10] What do we know about femvertising? A systematic literature review
    Vandellos, Emma
    Villarroya, Anna
    Bote-Vericad, Juan-Jose
    CUADERNOS INFO, 2023, (56) : 185 - 204